CVE-2024-37863: Buffer Overflow
Published Dec 5, 2024
·Updated
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a buffer overflow via the nav2amcl process. This vulnerability is triggered via sending a crafted .yaml file.
Affected Software
2 affected components
Open Robotics Robotic Operating System 2
Open Robotics Nav2
Event History
Dec 5, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37863?
CVE-2024-37863 has a high severity due to the potential for remote code execution via a buffer overflow.
2
How do I fix CVE-2024-37863?
Fix CVE-2024-37863 by applying the latest patches for Open Robotics Robotic Operating System 2 and Nav2.
3
Which versions are affected by CVE-2024-37863?
CVE-2024-37863 affects humble versions of Open Robotics Robotic Operating System 2 (ROS2) and Nav2.
4
What triggers the vulnerability CVE-2024-37863?
The CVE-2024-37863 vulnerability is triggered by sending a crafted .yaml file to the nav2_amcl process.
5
Can CVE-2024-37863 be exploited remotely?
Yes, CVE-2024-37863 can be exploited remotely due to its nature as a buffer overflow vulnerability.